יום ראשון, 4 באוקטובר 2026 LIVE
AI־INFO

כתבה arXiv cs.AI ·

חלוקה והזרקה: האם סוכנים יכולים לשחזר הזרקת פרומפט עקיף מרסיסים?

Divide and Inject: Can Agents Reconstruct an Indirect Prompt Injection from Fragments?
AdaLCPI היא שיטה להזרקת פרומפט עקיף באמצעות רסיסים. היא משתמשת בחיפוש מותאם ובמשוב מהסוכן. השיטה השיגה הצלחה גבוהה יותר מבסיסי האימון הקיימים.
תקציר מקורי באנגליתarXiv:2609.36576v1 Announce Type: new Abstract: Agentic systems are now being widely used to orchestrate tools and reason over long contexts. However, the improving capabilities of the large language models powering these agents also create new attack surfaces for indirect prompt injection. In particular, an attacker may not need to place a complete malicious instruction in retrieved content if the agent can reconstruct the objective from incomplete fragments distributed across a long context. In this work, we introduce adaptive long-context prompt injection (AdaLCPI), which combines long-context fragmentation with adaptive search. AdaLCPI splits an attack objective into incomplete fragments, embeds them in external content retrieved through the agent's tools, and uses a reconstruction cue
קרא במקור המקורי